Application Security News and Articles


IBM Consulting partners with Microsoft to help clients modernize security operations

IBM Consulting and Microsoft announce strengthened cybersecurity collaboration to help clients simplify and modernize their security operations, and manage and protect their hybrid cloud identities. As organizations embrace hybrid cloud and AI to ...

SEC Disclosure Inconsistencies Amid Snowflake Breach | Kovrr

Articles related to cyber risk quantification, cyber risk management, and cyber resilience. The post SEC Disclosure Inconsistencies Amid Snowflake Breach | Kovrr appeared first on Security Boulevard.

Redefining Security: The Power of Passwordless Authentication

Redefining Security: The Power of Passwordless Authentication josh.pearson@t… Tue, 07/02/2024 - 07:01 In the face of rapidly evolving cyber threats, the traditional method of securing sensitive information through passwords has become ...

Leveraging no-code automation for efficient network operations

In this Help Net Security interview, Lingping Gao, CEO at NetBrain, discusses the challenges NetOps teams face in maintaining production services due to outdated processes and growing infrastructures. No-code automation has the potential to ...

The impossibility of “getting ahead” in cyber defense

As a security professional, it can be tempting to believe that with sufficient resources we can achieve of state of parity, or even relative dominance, over cyber attackers. After all, if we got to an ideal state – fully staffed teams of ...

Inside the minds of CISOs

In this Help Net Security video, Nick McKenzie, CISO of Bugcrowd, discusses the key findings from their recent report, which comes at a crucial time as security leaders’ roles are being discussed more with the current risk landscape and the ...

Deepfakes and voice clones are undermining election integrity

As the volume of digital business rises year over year, the potential for AI-enhanced digital fraud increases with it, according to TeleSign. A new TeleSign report highlights consumer concerns and uncertainty about how AI is being deployed, ...

OpenSSH Remote Code Execution Vulnerability (CVE-2024-6387) Notification

Overview Recently, NSFOCUS CERT detected that OpenSSH issued a security announcement and fixed the remote code execution vulnerability of OpenSSH (CVE-2024-6387). Due to a signal handler race condition issue in OpenSSH Server (sshd) under the ...

An Identity Love Story: Hardware vs Software Security Tokens

Identity Security Cybersecurity has been growing since the first computer was created. And it is... The post An Identity Love Story: Hardware vs Software Security Tokens appeared first on Axiad. The post An Identity Love Story: Hardware vs ...

Infostealers on the Rise: A New Wave of Major Data Breaches?

This blog continues our previous article, The Resurgence of Major Data Breaches, where we discussed the alarming increase infostealers in data breaches orchestrated by the notorious ShinyHunters group. In this part, we delve into the role of ...

A Playbook for Detecting the OpenSSH Vulnerability – CVE-2024-6387 – regreSSHion

The Qualys Threat Research Unit has discovered a new “high” severity signal handler race condition vulnerability in OpenSSH’s server software (sshd). According to the research, this vulnerability has the potential to allow remote ...

How to Add Your Logo to Gmail Emails: Gmail & Branded Emails

Reading Time: 7 min Craft stunning branded emails with Gmail layouts to grab attention & boost clicks. Bonus: Learn how to add a BIMI logo for ultimate brand verification & security! The post How to Add Your Logo to Gmail Emails: Gmail ...

Shadow Linking: The Persistence Vector of SaaS Identity Threat

Executive Summary The Obsidian Security Research Team has uncovered a persistence attack vector, Shadow Linking, which allows threat actors to gain persistent access via OpenID Connect (OIDC) login to victims’ SaaS accounts stealthily. ...

USENIX Security ’23 – WaterBear: Practical Asynchronous BFT Matching Security Guarantees of Partially Synchronous BFT

Authors/Presenters:Haibin Zhang, Sisi Duan, Boxin Zhao, Liehuang Zhu Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from ...

Life in the Swimlane with Mark Bjerke, Regional Sales Director

The post Life in the Swimlane with Mark Bjerke, Regional Sales Director appeared first on AI Enabled Security Automation. The post Life in the Swimlane with Mark Bjerke, Regional Sales Director appeared first on Security Boulevard.

regreSSHion: RCE Vulnerability in OpenSSH Server (CVE-2024-6387)

A high-severity remote code execution (RCE) vulnerability has been found in OpenSSH’s server (CVE-2024-6387) by the research team The post regreSSHion: RCE Vulnerability in OpenSSH Server (CVE-2024-6387) appeared first on ARMO. The post ...

More than 100K sites impacted by Polyfill supply chain attack

The new Chinese owner tampers with the code of cdn.polyfill.io to inject malware targeting mobile devices. The post More than 100K sites impacted by Polyfill supply chain attack appeared first on Security Boulevard.

Canada Day 2024 / La Fête du Canada 2024

Happy Canada Day 2024 / La Fête du Canada 2024 To Our Canadian Family & Friends! / A notre famille et nos amis canadiens! Permalink The post Canada Day 2024 / La Fête du Canada 2024 appeared first on Security Boulevard.

The Evolution of Phishing Attacks: Beyond Email and How to Protect Your Organization

The Evolution of Phishing Attacks: Beyond Email Phishing attacks have long been synonymous with email, but the landscape of cyberthreats has evolved dramatically. Today, phishing is not confined to email inboxes; it has permeated various ...

‘Russia’ Breaches TeamViewer — ‘No Evidence’ Billions of Devices at Risk

SolarWinds hackers strike again: Remote access service hacked—by APT29, says TeamViewer. The post ‘Russia’ Breaches TeamViewer — ‘No Evidence’ Billions of Devices at Risk appeared first on Security Boulevard.